Kubernetes RBAC Exploited for Cryptomining Across 2,000+ Clusters
Over 2,000 Kubernetes clusters compromised through RBAC misconfigurations. Attackers deploy cryptominers via default service accounts. Check your clusters now.
Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.
Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.
Updated October 3, 2026 — all 220 published advisories are browsable here. The four drawing the most attention right now: a FortiMail email-gateway flaw being exploited before any fix exists (CVE-2026-104286, rated 9 out of 10 for severity) — there is no patch yet, so every affected 8.0, 7.6, 7.4 and 7.2 system is relying on Fortinet’s workaround, starting with switching off the Identity Based Encryption portal if you do not use it; two Citrix NetScaler flaws exploited for weeks before the September 27 fix (CVE-2026-88771 and CVE-2026-88772) — a patched box can still be hosting a webshell (a hidden back door left behind in the software itself), so update to 14.1-73.37 or 13.1-64.23 and then go looking for what was left behind; a Roundcube webmail flaw that lets an attacker tamper with the mail database before anyone logs in (CVE-2026-48842), patched in May 2026 and still being exploited because it ships inside hosting control panels most firms forget they run; and a Microsoft SharePoint Server flaw under active attack that lets an intruder run their own code on the server holding your internal documents (CVE-2026-65660), whose CISA federal patch deadline passed on September 28, so an unpatched server is now overdue rather than pending. Two of the four are email systems, and one has no fix at all, which is why what decides the cost is how fast someone notices. If you are not sure who is reading the alerts at 2 a.m., our 24/7 staffed security operations center handles the detection and the response.
Over 2,000 Kubernetes clusters compromised through RBAC misconfigurations. Attackers deploy cryptominers via default service accounts. Check your clusters now.
Critical authentication bypass in Veeam Backup & Replication allows attackers to delete backup repositories without credentials.
Read moreSophisticated iOS exploit kit chains six vulnerabilities including three zero-days to achieve complete device takeover. Multiple threat actors including Russian espionage groups and commercial surveillance vendors observed using DarkSword against targets in Ukraine, Saudi Arabia, and Turkey.
Read moreNine critical vulnerabilities in budget IP KVM switches from GL-iNet, Angeet, Sipeed, and JetKVM allow unauthenticated code execution and hardware-level access.
Read moreCISA added CVE-2025-47813 (info disclosure) to KEV, used to enhance CVE-2025-47812 (CVSS 10.0 RCE) exploitation. Attackers chain both flaws for reliable remote access. Wing FTP patches available since May 2025. Federal deadline: March 30.
Read moreGoogle patched CVE-2026-3909 (Skia OOB write) and CVE-2026-3910 (V8 sandbox escape), both CVSS 8.8 and actively exploited. CISA added to KEV with March 27 deadline. Update to Chrome 146.0.7680.75/76.
Read moreGoogle patched CVE-2026-3909 (Skia OOB write) and CVE-2026-3910 (V8 implementation flaw), both actively exploited. Third Chrome zero-day emergency in 2026. Update to 146.0.7680.75/76 immediately.
Read moreCVE-2026-42071 (CVSS 9.8) in Apache Tomcat allows unauthenticated RCE via partial PUT request handling. Actively exploited 30 hours after disclosure.
Read moreA critical RCE vulnerability in Atlassian Confluence is being mass-exploited by multiple threat actors.
Read moreIvanti discloses another actively exploited zero-day chain in Connect Secure VPN appliances. CVE-2026-0778 and CVE-2026-0779 allow unauthenticated attackers ...
Read moreA critical vulnerability in Microsoft Teams allows attackers to deliver malware through specially crafted meeting invitations.
Read moreNation-state attackers are actively exploiting a critical zero-day in Palo Alto GlobalProtect VPN to breach defense contractors. If you run GlobalProtect, apply the emergency patch now or isolate affected systems from the network immediately.
Read moreA managed SOC gives you 24/7 threat monitoring from $50K/yr vs $1M+ in-house. Learn what is included, how pricing works, and how to pick the right provider.
Read moreA complete guide to penetration testing pricing in 2026. Learn what drives costs, price ranges by test type, red flags to watch for, and how to get real value from your security investment.
Read moreA practical guide to SOC 2 audit preparation covering Type I vs Type II, the five Trust Services Criteria, common gaps, evidence collection, and how to accelerate the certification timeline.
Read moreA practical guide to small business cybersecurity covering the essentials that actually matter: MFA, email security, backups, employee training, and when to outsource to professionals.
Read moreQualys discovered nine vulnerabilities in AppArmor affecting 12.6 million Linux servers. CrackArmor enables unprivileged users to achieve root via confused deputy attacks, bypass container isolation, defeat KASLR, and manipulate security policies. All kernels since 4.11 affected.
Read moreCISA added CVE-2025-68613 to KEV after confirming active exploitation of n8n automation platform. Five critical RCE vulnerabilities (CVSS 9.4-9.5) allow credential theft via encryption key extraction. 24,700 instances exposed. Federal deadline: March 25, 2026.
Read moreSentinelOne documents campaign targeting FortiGate appliances to extract AD/LDAP credentials. Attackers exploit CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858, decrypt config files, and harvest NTDS.dit. Healthcare, government, and MSPs are primary targets.
Read moreJFrog discovered malicious npm package @openclaw-ai/openclawai deploying GhostLoader RAT on macOS. The 11,700-line infostealer harvests Keychain, browser credentials, crypto wallets, SSH keys, cloud creds, and enables browser session cloning. 178 developers compromised.
Read moreOur CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.
Subscribe to our newsletter and get the latest security insights delivered to your inbox.